US2024430274A1PendingUtilityA1
Ransomware detection and/or remediation as a service in file server systems
Est. expiryJun 26, 2043(~16.9 yrs left)· nominal 20-yr term from priority
H04L 63/1416
43
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
Examples of analytics systems may include a cloud based no-touch auto-update mechanism that may have access to ransomware signatures. For example, the service may pull ransomware signatures from a centralized public datastore through APIs and update the ransomware signatures on file servers subscribed to the analytics system.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A system comprising:
a repository of ransomware signatures, each of the ransomware signatures including a pattern of file events indicative of a ransomware attack; an analytics system configured to periodically access a source of ransomware signatures and identify new or changed ransomware signatures and to provide changed or updated ransomware signatures to file servers subscribed to a ransomware signature update service.
2 . The system of claim 1 , wherein the analytics system is configured to prevent adding a ransomware signature from the repository to a particular file server when the particular client has previously blocked the ransomware signature.
3 . The system of claim 1 , wherein the analytics system is configured to allow additional ransomware signatures at a particular file server when the particular file server has added the ransomware signature.
4 . The system of claim 1 , wherein the analytics system is configured to detect a new ransomware signature based on a ransomware attack on one of the file servers, the analytics system further configured to distribute the new ransomware signature to other ones of the file servers.
5 . The system of claim 1 , wherein the analytics system comprises a listener service configured for periodic communication with the repository of ransomware signatures.
6 . The system of claim 1 , wherein the pattern of file events indicative of the ransomware attacks include a rename event.
7 . The system of claim 1 wherein at least one of the file servers includes a local ransomware signature repository, and wherein the changed or updated ransomware signatures are used to update the local ransomware signature repository.
8 . The system of claim 7 , wherein the at least one of the file servers is configured to remediate a ransomware attack based on the local ransomware signature repository.
9 . A method comprising:
periodically connecting to a ransomware signature repository to identify a new or changed ransomware signature, wherein the new or changed ransomware signature is based on a pattern of file events; comparing the new or changed ransomware signature with ransomware signatures stored locally at a file server; and updating the file server with the new or changed ransomware signature based on said comparing.
10 . The method of claim 9 , wherein said periodically connecting comprises transmitting an API call to the ransomware signature repository.
11 . The method of claim 9 , further comprising identifying a deleted ransomware signature based on the ransomware signature repository.
12 . The method of claim 9 , wherein said updating the file server comprises updating a behavior of a file blocking policy of the file server.
13 . The method of claim 9 , further comprising refraining from updating a second file server with the new or changed ransomware signature when the second file server had previously removed the new or changed ransomware signature.
14 . The method of claim 9 , further comprising determining a particular sequence of events has occurred previously at a second file server; and
refraining from updating the second file server with the new or changed ransomware signature when the new or changed ransomware signature includes the particular sequence of events.
15 . The method of claim 9 , further comprising:
identifying a second ransomware signature based on a ransomware attack occurring on the file server; and updating the ransomware signature repository with the second ransomware signature.
16 . The method of claim 9 , further comprising distributing the new or changed ransomware signature to multiple file servers in accordance with a prioritization rule.
17 . The method of claim 16 , wherein the prioritization rule comprises a rule which prioritizes distribution of the new or changed ransomware signature to file servers associated with a same tenant from which the new or changed ransomware signature was discovered.
18 . The method of claim 9 , further comprising identifying pre-existing infection on the file server based on the new or changed ransomware signature.
19 . The method of claim 9 , further comprising identifying a malicious client based on the new or changed ransomware signature.
20 . At least one non-transitory computer readable media encoded with instructions which, when executed, cause a system to perform operations comprising:
periodically connecting to a ransomware signature repository to identify a new or changed ransomware signature, wherein the new or changed ransomware signature is based on a pattern of file events; comparing the new or changed ransomware signature with ransomware signatures stored locally at a file server; and updating the file server with the new or changed ransomware signature based on said comparing.
21 . The non-transitory computer readable media of claim 20 , wherein the operations further comprise refraining from updating a second file server with the new or changed ransomware signature when the second file server had previously removed the new or changed ransomware signature.
22 . The non-transitory computer readable media of claim 20 , wherein the operations further comprise:
identifying a second ransomware signature based on a ransomware attack occurring on the file server; and updating the ransomware signature repository with the second ransomware signature.
23 . The non-transitory computer readable media of claim 20 , wherein the operations further comprise distributing the new or changed ransomware signature to multiple file servers in accordance with a prioritization rule.
24 . The non-transitory computer readable media of claim 23 , wherein the prioritization rule comprises a rule which prioritizes distribution of the new or changed ransomware signature to file servers associated with a same tenant from which the new or changed ransomware signature was discovered.Join the waitlist — get patent alerts
Track US2024430274A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.